Mechanism · Model identity attestation
Launch-state attestation does not by itself cover weights loaded later
On this page
SignificantTheoretical argumentMitigated
Attestation measures launch state, and weights are read from disk after boot. A signature checked at load time does not stop a malicious hypervisor from altering the disk afterwards 1. Tinfoil reports mitigating this with dm-verity checks on every read 1. Unmeasured runtime configuration remains a general risk 6.